US2019102533A1PendingUtilityA1

Peripheral Cyber-Security Device

Assignee: STRYKER CORPPriority: Oct 4, 2017Filed: Sep 25, 2018Published: Apr 4, 2019
Est. expiryOct 4, 2037(~11.2 yrs left)· nominal 20-yr term from priority
G06F 21/554H04L 63/1441H04W 12/06G06F 21/82H04W 4/029G06F 21/34H04L 63/0428H04L 63/1416H04L 63/0876H04L 63/0853G06F 21/567H04W 12/71H04L 63/0227H04W 12/63G06F 21/85
34
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A peripheral cyber-security device is provided for a host device, such as but not limited to a medical/surgical device to provide cyber-security features for the host device. The peripheral device and the host device are hardware specific such that the peripheral device is used solely for the specific host device. The devices authenticate using unique device ID handshaking and the peripheral device provides services, such as external firewall capabilities, data encryption, IP masking, tampering/intrusion mitigation (e.g., circuit breaking), and the like. A fleet of peripheral devices, used among a plurality of corresponding host devices, can be managed as part of a remote management service. The remote management service can remotely send updates to and monitor the peripheral devices and host devices.

Claims

exact text as granted — not AI-modified
1 . A system comprising:
 a host device configured to communicate over a network and comprising:
 a first processor; 
 a first memory component coupled to the first processor and configured to store a first unique device identifier (UDID) associated with the host device; and 
 a first interface coupled to the first processor; 
   a peripheral device being separate and distinct from the host device and comprising:
 a second processor; 
 a second memory component coupled to the second processor and configured to store a second UDID associated with the peripheral device; and 
 a second interface coupled to the second processor and with the second interface configured to physically and removably attach to the first interface to trigger evaluation of the UDIDs to establish authentication between the host device and the peripheral device such that the peripheral device is operable solely with the host device, and wherein the peripheral device is configured to implement cyber-security features for the host device relative to the network when authenticated. 
   
     
     
         2 . The system of  claim 1 , wherein the peripheral device is configured to open network access for the host device upon successful authentication between the host device and the peripheral device. 
     
     
         3 . The system of  claim 1 , wherein the peripheral device is configured to implement network encryption for data transmitted to the host device over the network and for data transmitted from the host device over the network. 
     
     
         4 . The system of  claim 1 , wherein the first and second interfaces are configured to implement hardware encryption. 
     
     
         5 . The system of  claim 1 , wherein the peripheral device is configured to implement an external firewall between the network and the host device. 
     
     
         6 . The system of  claim 1 , wherein the first and second UDIDs are associated with the first and second interfaces. 
     
     
         7 . The system of  claim 1 , wherein the peripheral device is configured to mask an IP address of the host device. 
     
     
         8 . The system of  claim 1 , wherein the peripheral device comprises an intrusion mitigation device configured to temporarily or permanently disable functionality of the peripheral device upon detection of an intrusion into the peripheral device from the network. 
     
     
         9 . The system of  claim 1 , wherein the peripheral device and the host device comprise a locking mechanism configured to lock the peripheral device and the host device to one another based on establishing authentication between the host device and the peripheral device. 
     
     
         10 . The system of  claim 1 , wherein the peripheral device comprises a location tracker configured to connect to a network to enable determining of a location of the peripheral device. 
     
     
         11 . The system of  claim 10 , wherein the location tracker of the peripheral device is a first location tracker and the system comprises a second location tracker such that the first location tracker is configured to communicate with the second location tracker when the first location tracker and the second location tracker are within a proximity of one another to enable determining a location of the peripheral device. 
     
     
         12 . A peripheral device for implementing cyber-security features for a host device, the host device configured to communicate over a network and comprising a first processor, a first memory component coupled to the first processor and configured to store a first unique device identifier (UDID) associated with the host device, and a first interface coupled to the first processor, the peripheral device being separate and distinct from the host device, the peripheral device comprising:
 a second processor;   a second memory component coupled to the second processor and configured to store a second UDID associated with the peripheral device; and   a second interface coupled to the second processor and with the second interface configured to physically and removably attach to the first interface to trigger evaluation of the UDIDs to establish authentication between the host device and the peripheral device such that the peripheral device is operable solely with the host device, and wherein the second processor of the peripheral device is configured to implement cyber-security features for the host device relative to the network when authenticated.   
     
     
         13 . The peripheral device of  claim 12 , wherein the second processor is configured to open network access for the host device upon successful authentication with the host device. 
     
     
         14 . The peripheral device of  claim 12 , wherein the second processor is configured to implement network encryption for data transmitted to the host device over the network and for data transmitted from the host device over the network. 
     
     
         15 . The peripheral device of  claim 12 , wherein the second interface is configured to implement hardware encryption with the first interface. 
     
     
         16 . The peripheral device of  claim 12 , wherein the second processor is configured to implement an external firewall between the network and the host device. 
     
     
         17 . The peripheral device of  claim 12 , wherein the second UDID is associated with the second interface. 
     
     
         18 . The peripheral device of  claim 12 , wherein the second processor is configured to mask an IP address of the host device. 
     
     
         19 . The peripheral device of  claim 12 , further comprising an intrusion mitigation device configured to temporarily or permanently disable functionality of the peripheral device upon detection of an intrusion into the peripheral device from the network. 
     
     
         20 . A remote management service implemented on a remote server and configured to remotely monitor and manage the peripheral device of  claim 12 . 
     
     
         21 . A method of providing cyber-security to the host device using the peripheral device as set forth in  claim 12 . 
     
     
         22 . A computer-implemented method for remotely monitoring a plurality of peripheral devices using a remote service implemented on a remote server, each peripheral device being configured to communicate with the remote server over a network, each peripheral device being uniquely paired with a corresponding host device such that each peripheral device is operable solely with the corresponding host device, each peripheral device comprising an interface configured to physically and removably attach to an interface of the corresponding host device for triggering an authentication process with the corresponding host device, and with each peripheral device being configured to implement cyber-security features for the corresponding host device when authenticated, the computer-implemented method comprising:
 communicating with the peripheral devices over the network using the remote server;   remotely monitoring, with the remote server, cyber-security features or behavior of the peripheral devices;   detecting, with the remote server, an occurrence relating to cyber-security features or behavior of one or more peripheral devices; and   executing, with the remote server, a computer-implemented action to address the occurrence.   
     
     
         23 . The computer-implemented method of  claim 22 , wherein remotely monitoring comprises the remote server monitoring any one or more of:
 location of each peripheral device;   usage of each peripheral device with the corresponding host device;   network or firewall activity of each peripheral device; and   software/firmware versions of the peripheral devices.   
     
     
         24 . The computer-implemented method of  claim 22 , wherein detecting the occurrence comprises the remote server detecting any one or more of:
 packet-level data intrusion of one or more peripheral devices;   physical tampering of one or more peripheral devices; and   outdated software/firmware of one or more peripheral devices.   
     
     
         25 . The computer-implemented method of  claim 22 , wherein executing the computer-implemented action comprises the remote server executing any one or more of the following actions:
 remotely disabling or destroying one or more peripheral devices; and   remotely updating outdated software/firmware of one or more peripheral devices.

Join the waitlist — get patent alerts

Track US2019102533A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.